Does ISO/IEC 42001 AI Management System require Risk Assessment?
OECD • voluntary
Yes — 1 provision
Requirements at a glance
This regulation imposes 4 specific requirements for Risk Assessment across 1 provision:
- Risk assessment — Establish processes to identify and assess AI-related risks
- Risk treatment — Implement controls to treat identified risks
- Objectives — Set measurable AI management objectives
- Leadership commitment — Top management must demonstrate commitment to the AI management system
AI Risk Management System #
Requirements
| Requirement | Details |
|---|---|
| Risk assessment | Establish processes to identify and assess AI-related risks |
| Risk treatment | Implement controls to treat identified risks |
| Objectives | Set measurable AI management objectives |
| Leadership commitment | Top management must demonstrate commitment to the AI management system |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | Voluntary — certification-based, no direct penalties |